VLAN Broadcast Restriction via Group Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless networks, access points face processing burdens due to multiple address translations for broadcast traffic, and existing techniques require static VLAN associations, which are not feasible in dynamic Enterprise Wireless LAN environments.

Innovation Solution

Implementing a VLAN by sending a unique group key to stations, encrypting frames addressed to the VLAN, and broadcasting them, allowing only keyed stations to decrypt, thereby reducing processing load and enabling dynamic VLAN membership without hard handoffs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an access point maintains a VLAN table and performs multiple address translations for broadcast traffic, then VLAN membership can be dynamically associated based on user policy, but the processing load on the access point increases and traffic throughput slows down

Engineering Contradiction:
Improvedynamic VLAN associationVSAvoidtraffic throughput
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments VLAN traffic handling by separating broadcast/multicast frame processing from unicast frame processing. The access point encrypts broadcast and multicast frames with VLAN-specific group keys before transmission, while unicast frames continue to use traditional address translation methods. This segmentation allows dynamic VLAN association to be maintained without imposing address translation overhead on all traffic types, thereby preserving traffic throughput while enabling adaptability.

Inventive Principle:
Principle #1Segmentation

2Productivity

If an access point is dedicated to a particular VLAN with unified membership, then the access point can simply broadcast VLAN messages without additional processing, but the access point cannot serve other VLANs and requires static association

Engineering Contradiction:
Improvebroadcast efficiencyVSAvoidVLAN flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent enables a single access point to serve multiple VLANs simultaneously by implementing multi-functionality. The access point maintains associations with multiple VLANs and encrypts broadcast frames with different group keys corresponding to different VLANs. This allows the access point to efficiently broadcast to multiple VLANs without requiring dedicated access points for each VLAN, thereby maintaining both broadcast efficiency and VLAN flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If broadcast frames are sent to all stations associated with a BSSID, then VLAN restriction is achieved, but stations without the appropriate group key can potentially access VLAN traffic

Engineering Contradiction:
ImproveVLAN restrictionVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by encrypting broadcast and multicast frames with VLAN-specific group keys. Each VLAN has its own encryption key, and only stations that possess the corresponding group key can decrypt and access the traffic. This ensures that while broadcast frames are sent to all stations associated with the BSSID for efficient delivery, only the intended VLAN members can actually read the content, thereby achieving both VLAN restriction and security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11463425B2Restricting broadcast and multicast traffic in a wireless network to a VLAN
Publication Date: 2022.10.04 FORTINET INC
  • US11463425B2 patent drawing
  • US11463425B2 patent drawing
  • US11463425B2 patent drawing

AI summary

Traffic broadcast to a VLAN is restricted. To do so, a plurality of stations are associated with a BSSID (basic service set identifier). A first VLAN is configured by sending a first group key to each station from the plurality of stations that is a member of the first VLAN, wherein each VLAN is associated with a unique group key. One or more frames addressed to the first VLAN are received. The one or more frames are encrypted with the first group key to prevent stations without the first group key from being able to decrypt the one or more frames. The one or more encrypted VLAN frames are broadcast to the plurality of stations associated with the BSSID.